New Android Malware Exfiltrates Data Through Nearby Devices, Targeting European Users
A sophisticated Android malware named Manic has been discovered by researchers at ThreatFabric, targeting users in multiple European countries with a novel data exfiltration mechanism that allows it to siphon sensitive information from compromised devices even when they are offline. The malware combines spyware, banking fraud, and remote control capabilities, making it a significant threat to Android users.
Manic has been active since at least February, with a primary focus on Ukraine, where it targets numerous banking, government, payment, crypto wallet, messaging, and authenticator/2FA apps. The malware’s authors have implemented an unusual fallback mechanism that enables data exfiltration through nearby infected devices over Wi-Fi Direct or Bluetooth connections. This means that even if a compromised device cannot reach the command-and-control server, it can still transmit stolen data to its operators.
The malware uses transparent overlays on legitimate applications’ numeric keypads to capture victims’ taps and reproduce them through Android Accessibility. Once granted Accessibility permissions, Manic can capture lock PIN/passwords, intercept notifications and SMS messages, collect files and location data, monitor the screen, and provide remote control to operators via WebRTC sessions. The captured information is categorized by type, making it more readily exploitable for the malware authors.
What’s particularly concerning about Manic is its ability to adapt and persist on compromised devices. ThreatFabric researchers noted that the malware has been updated several times since its discovery, with the latest version featuring stronger anti-analysis checks and in-memory DEX loading. This suggests that the attackers are continually refining their tactics to evade detection and stay one step ahead of security measures.
The implications of Manic’s data exfiltration mechanism are significant. Since it allows compromised devices to transmit sensitive information even when they’re offline, users may not even realize their device has been breached until it’s too late. This highlights the importance of maintaining robust security practices, including regular software updates, strong passwords, and cautious app installation habits.
To protect themselves from Manic and similar threats, Android users should exercise caution when downloading APKs from obscure sources or unofficial portals. Denying Accessibility permissions unless required by a trusted application is also crucial, as this can prevent malware like Manic from gaining the necessary privileges to operate. Regularly running Play Protect scans can help detect and remove known malware, but it’s essential to stay vigilant and monitor device behavior closely.
As the threat landscape continues to evolve, users must remain informed about emerging threats like Manic. By taking proactive steps to secure their devices and being aware of potential vulnerabilities, we can all contribute to a safer online environment.
Source: Bleeping Computer — 2026-08-20